Record summary

CVE-2019-5434 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third party websites. This vulnerability was addressed in version 4.2.0.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 9, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Revive Adserver

CVE ListFixed version v4.2.0affected
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBRevive Adserver 4.2 - Remote Code ExecutionExploitDB exploitby crlfNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALRevive Adserver 4.2 - Remote Code ExecutionCVSS 9.8

Revive Adserver 4.2 is susceptible to remote code execution. An attacker can send a crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. This can be exploited to perform various types of attacks, e.g. serialize-related PHP vulnerabilities or PHP object injection. It is possible, although unconfirmed, that the vulnerability has been used by some attackers in order to gain access to some Revive Adserver instances and deliver malware through them to third-party websites.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.

Remediation

Apply the latest security patches or upgrade to a newer version of Revive Adserver.

WeaknessesCWE-502
Authorsomarjezi
Template tagscvecve2019edbpacketstormreviveadserverrcerevive-sasvulnvkev
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:revive-sas:revive_adserver:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:106844876
Shodan: http.title:"revive adserver"
FOFA: icon_hash=106844876
FOFA: title="revive adserver"
Google: intitle:"revive adserver"

Source: ProjectDiscovery

References

5